Executive brief
MetaGPT, a multi-agent framework for AI software development, is vulnerable to a security flaw that allows attackers to execute unauthorized commands on the underlying system. By providing a maliciously crafted filename (for example, within a cloned repository), an attacker can trick the software into running arbitrary code. This could lead to a full system compromise, unauthorized data access, or disruption of AI development operations.
Technical details
An OS command injection vulnerability exists in FoundationAgents MetaGPT up to version 0.8.1 within the `get_mime_type` function in `metagpt/utils/common.py`. The root cause is the use of `shell_execute()` with an f-string command, which internally triggers `subprocess.run` with `shell=True`. An attacker can exploit this by providing a maliciously crafted filename containing shell metacharacters (e.g., via a cloned repository processed by `repo_to_markdown`). This allows for arbitrary code execution with the privileges of the application. While a pull request (#1983) has been proposed to use list-based arguments to disable shell interpretation, it has not yet been merged.
Affected products
- FoundationAgents MetaGPT <= 0.8.1
Timeline
- 2026-02-04: disclosed: Issue #1930 opened on GitHub
- 2026-03-25: other: Pull request #1983 submitted to fix the vulnerability
- 2026-04-09: advisory: GitHub Advisory and CVE-2026-5973 published